67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9phorpiex: 67ae1ba4 — sextortion spam bot $800 variant, mutex t1, "YOU PERVERT!" window title
Executive Summary
Self-contained MSVC 9.0 PE32 sextortion spam bot, compiled 2026-05-29 12:13:57 UTC. Mutex t1, $800 BTC ransom demand, wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Same Tmlr XOR+NOT decrypt key and SMTP engine as the t2/t4/t5 siblings. New delta: window title string YOU PERVERT! I RECORDED YOU! (not observed in prior siblings). Static-only — CAPE skipped (no Windows guest).
What It Is
- SHA-256:
67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9 - File: PE32 executable (GUI) Intel 80386, 5 sections, 18 944 bytes ^[file.txt]
- Compile time: 2026-05-29 12:13:57 UTC (PE timestamp
0x6A198305) ^[pefile.txt:34] - Toolchain: MSVC 9.0 / MSVCR90.dll static CRT, LinkerVersion 9.0 ^[pefile.txt:45] ^[rabin2-info.txt:17]
- Linker flags:
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE,NX_COMPAT,TERMINAL_SERVER_AWARE^[pefile.txt:74] - YARA:
PE_File_Generic,Suspicious_Wininet_Imports^[yara.txt] - OpenCTI labels:
dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] - SSDeep:
192:NIISCngTBvblVPT0Y76fIkq2NleQY9T4KUSvu9zw+ggSmOiMbO5Ot1EdkF39TGJ4:PIblVP4Y/2N0bLu9JgPL7Nyav8U9c8^[ssdeep.txt]
How It Works
Entry & Mutex Gating
main() sleeps 2000 ms, creates mutex t1 via CreateMutexA ^[r2:main]. If GetLastError() == ERROR_ALREADY_EXISTS (0xB7), the process exits cleanly — single-instance enforcement. ^[r2:main]
Self-Erasure — Zone.Identifier ADS Deletion
Resolves its own module path via GetModuleFileNameW, formats %s:Zone.Identifier, and deletes the ADS via DeleteFileW. This removes the "Downloaded from Internet" mark that Windows adds to browser-downloaded files. ^[r2:main] ^[strings.txt:19]
External IP Discovery
Calls fcn.00401800 which opens http://icanhazip.com/ via InternetOpenA / InternetOpenUrlA (WinInet), reads the response, and wraps it in [%s] brackets. If the fetch fails, falls back to [0.0.0.0]. ^[r2:fcn.00401800] ^[strings.txt:18]
String Decryption — XOR+NOT (Tmlr key)
All SMTP strings and email template strings are stored encrypted in .rdata. fcn.00401030 decrypts in-place using a 4-byte key Tmlr (0x546d6c72): each plaintext byte = NOT(ciphertext_byte ^ key_byte[key_index % 4]). ^[r2:fcn.00401030]
This is the identical decrypt key used by siblings edd6ad22, 150e4652, c3b1b4e4, dc2936ea, and 5076fdc3. ^[entities/phorpiex.md]
SMTP Engine — Self-Contained Spam Dispatch
fcn.004024e0 (threadproc spawned by main) drives the spam loop:
- Seed PRNG with
GetTickCount()viasrand. - Download victim list from a C2 URL (decrypted at runtime) via
fcn.00401900, which usesInternetOpenWwith Chrome/202 UA and writes the response to%TEMP%\<n>.txt. - Parse victims from the downloaded text file — splits on
:,//,@to extract email addresses and SMTP server details. ^[r2:fcn.00402340] - Spawn 50 worker threads per outer iteration (outer loop runs 100 iterations = up to 5 000 total threads), each calling
fcn.00401a10to perform a full SMTP dialogue:HELO/EHLOhost ^[r2:fcn.00401a10]MAIL FROM:(sender spoofed from victim's own domain) ^[r2:fcn.00401a10]RCPT TO:^[r2:fcn.00401a10]DATAwith full email body ^[r2:fcn.00401a10]QUIT^[r2:fcn.00401a10]
- Email body assembly includes a forged
Received:header claiming MailEnable ESMTP, random IP octets, and the full sextortion template (see Interesting Tidbits). - Sleeps 20 s between outer loops, then deletes the temp file and re-fetches.
Thread Count
The outer loop runs 100 iterations, inner loop spawns 50 threads each = 5 000 concurrent SMTP threads, matching the t2/t4/t5 sibling configuration. ^[r2:fcn.004024e0]
Decompiled Behavior
entry0 (0x00402bb7)
Standard MSVC 9.0 CRT startup: GetStartupInfoA, InterlockedCompareExchange spinlock on module init, _initterm_e, _initterm, then calls main. No initterm hijack — honest CRT flow. ^[r2:entry0]
main (0x00402740)
Sleep(2000);
CreateMutexA(NULL, FALSE, "t1");
if (GetLastError() == ERROR_ALREADY_EXISTS) exit;
DeleteFileW("<self>:Zone.Identifier");
WSAStartup(0x0202, &wsaData);
if (DnsQuery_A("yahoo.com", ...) == 0) {
// decrypt C2 URL with Tmlr key
fcn.00401030(encrypted_C2);
wsprintfA(buffer, "%s", decrypted_C2);
CreateThread(NULL, 0, fcn.004024e0, buffer, 0, NULL);
Sleep(0xcdfe600); // ~216 000 000 ms (~60 hours)
}
ExitProcess(0);
The long Sleep at the end is a simple anti-triage / anti-emulation gate — the process stays alive but idle after spawning the spam thread. ^[r2:main]
fcn.00401030 — Decryptor
Iterates encrypted string, XORs with Tmlr key bytes cycling, then applies bitwise NOT. Writes result in-place. ^[r2:fcn.00401030]
fcn.004024e0 — Spam Thread Dispatcher
srand(GetTickCount());
strcpy(dest, decrypted_C2_URL);
ExpandEnvironmentStringsW("%temp%", ...);
wsprintfW(temp_path, "%sn.txt", temp_dir);
// download victim list
fcn.00401900(1, temp_path, decrypted_URL);
atoi(response) → thread_count;
for (i = 0; i < 100; i++) {
for (j = 0; j < 50; j++) {
CreateThread(NULL, 0, fcn.00402340, temp_path, 0, NULL);
Sleep(rand() % 50 + 50);
}
Sleep(20000);
}
DeleteFileW(temp_path);
ExitProcess(0);
^[r2:fcn.004024e0]
C2 Infrastructure
- External IP check:
http://icanhazip.com/(cleartext HTTP) ^[strings.txt:18] - Primary C2: Runtime-decrypted via
TmlrXOR+NOT cipher; not recoverable statically. The encrypted blob is at0x4041c0in.rdata. - User-Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36^[strings.txt:17] - DNS check:
yahoo.comMX resolution viaDnsQuery_Abefore C2 fetch — basic connectivity gating ^[r2:fcn.00401790] - SMTP server: Parsed from the downloaded victim list (format
user:pass@server:portor similar) ^[r2:fcn.00402340]
Interesting Tidbits
- Window title:
YOU PERVERT! I RECORDED YOU!— a new string not observed in thet2/t4/t5siblings. Likely used as a MessageBox or window caption if the binary is executed interactively. ^[strings.txt:146] - Same BTC wallet as t2/t4/t5:
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Campaign-level wallet reuse across at least four confirmed builds spanning ~18 minutes (t2 at 12:15:01, this sample at 12:13:57 — actually this sample predates t2 by ~1 minute, making it the earliest confirmed build in the burst). ^[strings.txt:59] - Chrome/202 UA masquerade: Impossible Chrome version
202.0.4664.110(Chrome stable has never reached v202). Same UA ast4/t5andedd6ad22($800 mutexetyueu). ^[strings.txt:17] - No ZIP attachment: Like
t2/t4/t5, the email body is plain text — no ZIP constructor. Earlier $1200 variants (150e4652) included a manual ZIP header assembly. This confirms the $800 sub-cluster dropped the ZIP payload. ^[entities/phorpiex.md] - MailEnable ESMTP masquerade: Forged
Received:header claimsMailEnable ESMTPto lend legitimacy. ^[strings.txt:27] - Sleep(60h) gate: The main thread sleeps for ~60 hours after spawning the spam thread — a crude but effective anti-sandbox evasion; most sandboxes time out long before the process exits. ^[r2:main]
- GetTickCount PRNG seeding: Both the downloader and the spam dispatcher seed
srandwithGetTickCount(), giving thread-sleep jitter that varies per execution. ^[r2:fcn.004024e0]
Deploy / ATT&CK
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE with social-engineered name |
| Data Encrypted for Impact | T1486 | Sextortion email demands $800 BTC ransom |
| Application Layer Protocol: Web Protocols | T1071.001 | HTTP C2 fetch via WinInet (icanhazip.com, encrypted payload URL) |
| Application Layer Protocol: Email | T1071.003 | Self-contained SMTP engine (WS2_32 socket → connect → send/recv) |
| Exfiltration Over C2 | T1041 | External IP check + victim-list download over HTTP |
| Data Manipulation: Transmitted Data | T1565.002 | Sextortion email body is a fabricated narrative (no actual video) |
| Masquerading | T1036 | Fake MailEnable ESMTP Received header; Chrome/202 impossible UA |
| Anti-Forensics: Data Destruction | T1070.004 | DeleteFileW on self :Zone.Identifier ADS; temp file deletion after spam loop |
| Anti-Analysis: Emulation Evasion | T1497.001 | 60-hour Sleep gate; GetTickCount PRNG seeding |
| Discovery: System Owner/User Discovery | T1033 | External IP fetch to personalize email headers |
Deployable Signatures
YARA
rule phorpiex_sextortion_800_variant {
meta:
description = "Phorpiex sextortion spam bot $800 variant (mutex t1/t2/t4/t5)"
author = "triage-pipeline"
date = "2026-09-02"
sha256 = "67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9"
strings:
$mutex_t1 = "t1" ascii wide
$mutex_t2 = "t2" ascii wide
$mutex_t4 = "t4" ascii wide
$mutex_t5 = "t5" ascii wide
$decrypt_key = "Tmlr" ascii
$btc_wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
$ua = "Chrome/202.0.4664.110 Safari/537.36" ascii
$extip = "http://icanhazip.com/" ascii
$mailenable = "MailEnable ESMTP" ascii
$window_title = "YOU PERVERT! I RECORDED YOU!" ascii wide
$sextortion_1 = "Unfortunately, there is some bad news for you." ascii
$sextortion_2 = "I RECORDED YOU (through your camera) MASTURBATING!" ascii
$sextortion_3 = "All you need is $800 USD in Bitcoin (BTC)" ascii
$func_1 = { 55 8b ec 83 ec 10 a1 ?? ?? ?? ?? 89 45 f4 } // decryptor prologue
condition:
uint16(0) == 0x5a4d and
filesize < 25KB and
(
($decrypt_key and $btc_wallet) or
($ua and $extip and any of ($mutex*)) or
(2 of ($sextortion*) and $btc_wallet) or
($window_title and $mailenable)
)
}
Behavioral Fingerprint
A PE32 GUI executable under 25 KB, compiled with MSVC 9.0 and linked against MSVCR90.dll, imports WININET.dll, WS2_32.dll, DNSAPI.dll, KERNEL32.dll, and USER32.dll. On launch it creates a named mutex (t1, t2, t4, or t5), deletes its own Zone.Identifier ADS, resolves yahoo.com via DnsQuery_A, fetches an external IP via http://icanhazip.com/, decrypts a C2 URL with the 4-byte key Tmlr (XOR+NOT), downloads a victim list to %TEMP%\<n>.txt, and spawns 50–5000 SMTP worker threads that connect to attacker-provided mail servers and send sextortion emails demanding $800 BTC to 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. The main thread then sleeps for ~60 hours. Network traffic shows cleartext HTTP to icanhazip.com and SMTP over port 25/587/465 with forged MailEnable ESMTP headers.
IOC List
| Type | Value |
|---|---|
| SHA-256 | 67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9 |
| SHA-1 | 4a077a0ed10d4bf84244f50e243608c8a41734bd (.text section) |
| MD5 | 787720059300256f7d5e3159ccbe51d7 (.text section) |
| Mutex | t1 (this sample); also t2, t4, t5 in campaign siblings |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
| Decrypt key | Tmlr (XOR+NOT) |
| User-Agent | Mozilla/5.0 ... Chrome/202.0.4664.110 Safari/537.36 |
| External IP URL | http://icanhazip.com/ |
| Temp file pattern | %TEMP%\<n>.txt |
| Window title | YOU PERVERT! I RECORDED YOU! |
| SMTP header forgery | Received: from ... with MailEnable ESMTP |
Detection Signatures
- capa — signatures not available (capa failed due to missing signature database) ^[capa.txt]. Static detection should rely on YARA + behavioral fingerprint.
- MITRE ATT&CK — see Deploy/ATT&CK table above.
References
- phorpiex — cluster entity page
- /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html — sibling
t5($800 variant) - /intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html — sibling
t4(twin oft5, 44 s earlier) - /intel/analyses/5076fdc39445369e67daaccb7ec1699107a5f227aaaec978ec9d77d966124f3d.html — sibling
t2(earliest confirmed build in burst) - /intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html — sibling
etyueu($800 variant, earlier campaign) - /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — $1200 variant (ZIP constructor present)
- OpenCTI artifact:
b9de1f15-fd21-4b79-8ec1-312e6a0c8d62
Provenance
Static analysis performed on pp-hermes (Linux 6.14.8-2-pve) using radare2 5.9.8. Strings from strings.txt and radare2 /iz. Decompilation via pdc. PE metadata from pefile.txt. File type from file.txt. No dynamic execution — CAPE skipped due to no Windows guest available.